Domain Map and Weighting Strategy

Key Takeaways

  • The largest MD-102 domain is Manage and maintain devices at 30-35 percent of the exam.
  • Prepare infrastructure for devices is the second-largest domain at 25-30 percent and heavily supports the rest of the blueprint.
  • Manage applications and Protect devices are each 15-20 percent, so together they can represent 30-40 percent of the exam.
  • Prepare plus Manage and maintain can account for 55-65 percent of the exam, so enrollment, provisioning, configuration, and operations need the most practice.
  • Weighting should guide time allocation, but every domain needs hands-on scenario practice because Microsoft often blends identity, compliance, apps, and security in one question.
Last updated: June 2026

Current Skills-Measured Map

The official MD-102 study guide lists four skills-measured domains effective as of April 28, 2026. Use these weights to decide where to spend hands-on practice time, but do not read them as isolated silos. Endpoint administration is integrated work: a single Windows Autopilot deployment can touch device groups, an Enrollment Status Page, Microsoft 365 Apps installation, compliance policy, BitLocker, and update rings all at once.

A common trap on the exam and in third-party study material is mis-stating these weights. Some blogs collapse the blueprint into a single "Manage, maintain, and protect" domain at 40-45 percent. That is not the current official structure. Verify against Microsoft Learn and study the four domains below.

DomainWeightCore study focusHigh-yield decisions
Prepare infrastructure for devices25-30%Microsoft Entra device join and registration, Intune enrollment, roles, compliance, Conditional Access, Windows Hello for Business, Windows LAPS, local group membershipJoin type, enrollment method, compliance requirement, access condition
Manage and maintain devices30-35%Windows Autopilot, provisioning packages, Windows 11 upgrades, Windows 365 Cloud PCs, configuration profiles, filters, Intune Suite capabilities, remote actions, monitoringDeployment mode, profile type, assignment scope, remote remediation action
Manage applications15-20%App packaging, deployment, Microsoft 365 Apps, Office policies, app stores, app protection, app configurationRequired versus available app, managed app versus managed device, Office deployment path
Protect devices15-20%Antivirus, disk encryption, firewall, attack surface reduction, security baselines, Defender for Endpoint, update rings and platform updatesSecurity profile choice, Defender onboarding, update policy, encryption recovery

Weighting Strategy

For an 80-hour study budget, a proportional plan would roughly look like this. The math is intentionally weighted toward the two largest domains, which together can be 55-65 percent of the exam.

Study bucketSuggested hoursWhy
Prepare infrastructure22It creates the identity, enrollment, compliance, and access foundation for many scenario questions.
Manage and maintain28It is the largest domain and includes deployment, configuration, Intune Suite, remote actions, and monitoring.
Manage applications14It is smaller by weight, but app deployment and app protection are common real-world decision points.
Protect devices16It overlaps with compliance, Defender, encryption, update management, and security operations.

Notice that the smaller domains still receive meaningful time. A 15-20 percent domain can easily be 8-12 questions. Skipping it to over-invest in a domain you already know is how strong candidates lose a borderline pass.

How to Read Cross-Domain Questions

When a question mentions a domain-specific tool, do not stop there. Ask what the business requirement is. If the requirement is to block access until a device meets policy, compliance and Conditional Access are central. If the requirement is to protect corporate data in apps without enrolling personal devices, app protection is central. If the requirement is to deploy brand-new Windows devices remotely with a known user experience, Autopilot and Enrollment Status Page design are central. The tool named in the question is sometimes a distractor; the requirement is the real signal.

A useful weekly review pattern is to pick one operational story and map it across all four domains. Example: deploy 500 Windows 11 laptops to remote employees. Prepare covers Microsoft Entra join, groups, enrollment, and compliance. Manage and maintain covers Autopilot, configuration profiles, filters, and remote actions. Manage applications covers Microsoft 365 Apps and required line-of-business apps. Protect devices covers BitLocker, Defender for Endpoint onboarding, attack surface reduction, and update rings. One story exercises the entire blueprint and reveals which domain you cannot yet narrate end to end.

What to Practice First

  1. Build confidence in join, registration, enrollment, compliance, and Conditional Access, because these concepts are prerequisites for many other tasks.
  2. Drill Windows Autopilot, Enrollment Status Page, configuration profiles, filters, remote actions, Windows 365, and Intune Suite capabilities, because this is the heaviest domain.
  3. Practice app deployment and mobile app protection scenarios separately so you do not confuse device management with app-level data protection.
  4. Tie endpoint security settings to outcomes: encryption, antivirus, firewall, attack surface reduction, baseline posture, Defender onboarding, and update reporting.

If you must triage limited study time, master Prepare and Manage and maintain first, then layer in the app and protection domains once your identity-and-enrollment foundation is solid.

Why the Weights Should Not Become Blinders

The weights tell you where the most questions live, but they do not tell you which questions you will get right. A candidate who is already fluent in Autopilot can earn more incremental points by shoring up a weak Protect devices domain than by re-reviewing deployment for the fifth time. Use the weights to set a starting budget, then re-allocate toward your measured weak spots after each practice round. Treat the percentages as a planning tool, not a ceiling.

It also helps to remember that the bullet points under each domain in the official study guide are the real syllabus. The percentage is an aggregate; the bullets are what gets tested. Read every bullet and confirm you can perform the task or explain the decision. For example, under Manage and maintain devices you will find "Run a device query by using KQL" and "Rotate BitLocker recovery keys" — narrow, concrete skills that a percentage figure alone would never reveal.

A Quick Domain Self-Test

Before your final week, try to write one sentence for each of these prompts without notes: which join type for cloud-first corporate laptops; which enrollment for shared Android scanners; which policy reports BitLocker versus enables it; which Autopilot mode for kiosks; which profile type for the broadest Windows settings; and which remote action removes company data but keeps personal data. If you stumble on any of these, you have found exactly where your weighted study time should go next, regardless of which domain it lives in.

Test Your Knowledge
Multi-Select

Which study priorities best reflect the current MD-102 domain weights? Select all that apply.

Select all that apply

Spend the most time on Manage and maintain devices because it is weighted 30-35 percent.
Treat Prepare infrastructure for devices as optional because enrollment is only a setup task.
Keep Manage applications and Protect devices in the plan because together they can account for 30-40 percent.
Ignore Microsoft Entra device state when studying Intune because identity is outside the exam.
Practice cross-domain scenarios where deployment, apps, compliance, and security appear together.
Test Your Knowledge
Matching

Match each task to the most directly related MD-102 domain.

Match each item on the left with the correct item on the right

1
Choose the appropriate Microsoft Entra device join type
2
Create an Enrollment Status Page for Windows Autopilot
3
Configure app protection policies for managed apps
4
Create disk encryption and attack surface reduction policies